CVE-2026-11774

EUVD-2026-36293
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Directory Server 11.5 E4S for RHEL 8
8060020260702180044.0ca98e7e ≤
𝑥
< *
ADP
Red HatRed Hat Directory Server 11.7 E4S for RHEL 8
8080020260702180836.f969626e ≤
𝑥
< *
ADP
Red HatRed Hat Directory Server 11.9 for RHEL 8
8100020260702145313.37ed7c03 ≤
𝑥
< *
ADP
Red HatRed Hat Directory Server 12.2 E4S for RHEL 9
9020020260703060155.1674d574 ≤
𝑥
< *
ADP
Red HatRed Hat Directory Server 12.4 E4S for RHEL 9
9040020260703055735.1674d574 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:3.2.0-8.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:3.0.6-19.el10_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:1.3.11.1-13.el7_9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260626120929.25e700aa ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
8040020260629123121.96015a92 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
8040020260629123121.96015a92 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
8060020260626130540.824efc52 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
8060020260626130540.824efc52 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
8080020260630025241.6dbb3803 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
8080020260630025241.6dbb3803 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:2.8.0-8.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:2.2.4-19.el9_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:2.4.5-26.el9_4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:2.6.1-22.el9_6 ≤
𝑥
< *
ADP
Red HatRed Hat Directory Server 13.2
1783452100 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
389-ds-base
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
sid
vulnerable
trixie
vulnerable
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
389-ds-base
RHEL 9
0:2.8.0-8.el9_8
fixed
389-ds-base-devel
RHEL 9
0:2.8.0-8.el9_8
fixed
389-ds-base-libs
RHEL 9
0:2.8.0-8.el9_8
fixed
389-ds-base-snmp
RHEL 9
0:2.8.0-8.el9_8
fixed
python3-lib389
RHEL 9
0:2.8.0-8.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
389-ds-base
Amazon Linux 2
0:1.3.10.2-17.amzn2.0.7
fixed
389-ds-base-debuginfo
Amazon Linux 2
0:1.3.10.2-17.amzn2.0.7
fixed
389-ds-base-devel
Amazon Linux 2
0:1.3.10.2-17.amzn2.0.7
fixed
389-ds-base-libs
Amazon Linux 2
0:1.3.10.2-17.amzn2.0.7
fixed
389-ds-base-snmp
Amazon Linux 2
0:1.3.10.2-17.amzn2.0.7
fixed
References